How SNcode works with your instance
Last reviewed: September 30, 2026
SNcode is a desktop app for macOS and Windows that connects to a ServiceNow instance and uses an AI to help you build on it. Connecting a third-party tool to a system that holds your (or your client's) tickets, user data, and configuration is a real decision. This page describes exactly how that works: connection, data flow, execution, and what we have and haven't done yet. Everything below applies identically on both platforms unless a section calls out a difference.
How does SNcode connect to my instance?
SNcode connects over the ServiceNow REST API using HTTP Basic authentication, with the username and password (or a REST-enabled account) you enter for each instance. When an instance rejects Basic auth (for example, SSO/MFA-only accounts), SNcode falls back to driving an authenticated browser session for that instance.
The connection is desktop-to-instance and direct. SNcode builds the authorization header on your machine and talks to your instance from your machine. There is no SNcode server between the app and your ServiceNow instance.
What does SNcode install on my instance?
Nothing. SNcode is not a plugin, a scoped application, or a store entry. There is no update set to import and no platform version to upgrade to. It authenticates as an account you already control and uses the REST API and UI that instance already exposes, which is also why it works against older releases and against client instances where you have credentials but no ability to install anything.
Where are my credentials stored?
Instance URLs and credentials are stored locally in a SQLite database on your own machine, at ~/.sncode/ on macOS and %USERPROFILE%\.sncode\ on Windows, encrypted at rest with SQLCipher. The database key is generated per user and sealed by the operating system's own secure storage (via Electron): the macOS Keychain on Mac, DPAPI on Windows. It lives only in the app's main process at runtime and is never written to disk in the clear.
Your ServiceNow credentials never reach our servers
What data goes where?
This is the part worth reading closely. Your ServiceNow credentials, chat history, and attached files are stored only on your machine. When you send a message, the conversation, including any ServiceNow query results or file excerpts it contains, is sent over TLS to the SNcode API. That is true in both of the ways SNcode can run the AI; they differ in what happens next.
Your machine, running SNcode
ServiceNow credentials + chat history in a local SQLCipher-encrypted database
Builds the ServiceNow auth header on-device
Your ServiceNow instance
No SNcode server sits between the app and your instance
SNcode API
Authenticates you and assembles the prompt
Processes it in transit; keeps token counts only, never content
Anthropic Claude API
Generates the response
Local Claude mode: the SNcode API assembles the prompt and hands it back instead of relaying it. Your locally installed Claude Code then calls Anthropic directly under your own subscription. In both modes, data the AI reads from your instance can become part of the prompt sent to the model.
SNcode API mode (Free, Core, Scale, Business Team, Business Scale, and the fallback tasks on Local plans): the SNcode API authenticates you, meters token usage, and relays the request to the Anthropic Claude API. Per Anthropic's commercial terms, API inputs and outputs are not used to train their models.
Local Claude mode (Local, Business Local, any paid plan when you choose to run locally, and the Free plan's 60-day trial): the SNcode API assembles the prompt from the team's instructions and your conversation and hands it back to the app. Your locally installed Claude Code then sends it to Anthropic under your own Claude subscription. Token usage counts against your own account; SNcode does not meter it.
In both modes, SNcode processes the conversation in transit only. It is not written to our database or to our logs. The only thing we keep from a request is its token count, in API mode, for quotas and billing.
Either way, remember the implication: data the AI reads from your instance can become part of the prompt sent to the model. Treat the AI request boundary accordingly.
What does SNcode store on its servers?
To operate accounts and enforce limits, the minimum:
- Account profile: email and user ID, plus name and avatar when you sign in with Google or Microsoft
- Aggregate token usage counts, for quotas and billing
- Subscription plan, seat count, and billing status (from Paddle, our payment processor)
- Bug reports you choose to send from the app, including any app logs you attach
SNcode does not store your ServiceNow credentials, conversation content, or attached files on its servers.
How does execution work, and can the AI change my instance on its own?
Not unless you let it. Execution goes through a review gate: when the AI proposes a script, SNcode shows you a plain-English description and the exact code, and nothing runs against your instance until you explicitly approve that action. The gate is on for every chat by default; if you switch on Skip confirmation in a chat's settings, scripts in that chat run without waiting for approval. See The Review Gate.
SNcode acts with the permissions of the connected account
What happens on disconnect or uninstall?
Deleting an instance in the app removes its stored credentials from the local database. Signing out closes the encrypted database. Your local data lives under ~/.sncode/ on macOS and %USERPROFILE%\.sncode\ on Windows. Removing the app does not automatically erase it; delete that folder to remove local data completely.
How are updates delivered?
Both builds are code-signed, and updates are delivered as signed builds. The macOS app uses hardened runtime and is notarized by Apple; the Windows installer and executables are signed through Azure Trusted Signing, so Windows can verify the publisher. We do not bundle third-party analytics or tracking SDKs. If you agree to log collection when signing in, the app sends operational logs (errors and timings, never conversation content) used to keep the service reliable; they are never sold or used for advertising.
Where are you in beta, honestly?
SNcode is in beta. What is true today: local-first architecture, ServiceNow credentials that stay on your machine, an encrypted-at-rest local database, review-gated execution (on by default), a notarized macOS build, and a signed Windows build. What we have not done yet: we do not hold a SOC 2 report or a third-party security audit, and we are not making compliance certifications. We would rather say that plainly than imply otherwise.
Security contact
Security questions or vulnerability reports: support@sncode.dev. For data handling and your rights, see our Privacy Policy.